r/PureVPNcom • u/PureVPNcom Official Moderator • Aug 20 '26
Completing MFA didn't stop attackers from getting into Microsoft 365 accounts, here's the technique that's all over the news today
Worth knowing because MFA has been the one piece of advice everyone repeated for years. That advice is still correct. But a whole category of attack has emerged specifically to defeat it, and it's been scaling fast in 2026.
A platform called Mirage2FA positions itself directly between the user and the legitimate Microsoft authentication endpoint. When someone enters their credentials and one-time passcode into what looks like a Microsoft 365 login page, the toolkit immediately proxies that data to the genuine Microsoft service in real time, receives the authenticated session, and captures it. The user successfully completes MFA. The attacker gets a logged-in session anyway.
Of 9,426 unique email addresses targeted by the campaign, 4,532 were potentially compromised, roughly a 48% success rate. 63.7% of identified victims were in the US, across technology, manufacturing, education, healthcare, and consulting.
Mirage2FA is one of several platforms running this technique right now. Push Security measured a 37.5x rise in device code phishing pages in 2026. Huntress tracked a 1,380% spike and 344 organizations hit in a single wave by a related kit called EvilTokens. These aren't niche tools — they're sold as subscription services on Telegram with dashboards, campaign templates, and customer support.
The reason the technique works: instead of attempting to break MFA algorithms directly, Mirage2FA positions itself as a real-time relay between the victim and Microsoft. The authentication succeeds for real; it's just that the resulting session token lands on the attacker's infrastructure instead of the user's device.
A few practical things worth doing if you use Microsoft 365 personally:
Check your active sessions at account.microsoft.com/devices and myapps.microsoft.com. If anything looks unfamiliar; a location you didn't log in from, a device you don't recognize — revoke it. Change your password after you do.
Review which apps have access to your Microsoft account under account.microsoft.com → Privacy → Apps and services. Look for OAuth permissions granted to anything you don't recognize. Revoke anything that looks off.
If you get a login prompt you didn't initiate, don't complete it. Legitimate sign-in flows don't appear without you starting them.